CVE-2005-4223
N/A
N/A
Summary
Multiple "potential" SQL injection vulnerabilities in Utopia News Pro (UNP) 1.1.4 might allow remote attackers to execute arbitrary SQL commands via (1) the newsid parameter in editnews.php, (2) the catid and question parameters in faq.php, (3) the poster parameter in postnews.php, (4) the tempid parameter in templates.php, and (5) the userid and groupid parameters in users.php.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.securityfocus.com/archive/1/419280/100/0/threaded
- http://www.osvdb.org/21649
- http://www.vupen.com/english/advisories/2005/2859
- http://glide.stanford.edu/yichen/research/sec.pdf
- http://secunia.com/advisories/17988/
- http://www.securityfocus.com/archive/1/419487/100/0/threaded
- http://www.osvdb.org/21647
- http://www.osvdb.org/21648
- http://www.osvdb.org/21645
- http://www.osvdb.org/21646
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23564
References
- http://www.securityfocus.com/archive/1/419280/100/0/threaded
- http://www.osvdb.org/21649
- http://www.vupen.com/english/advisories/2005/2859
- http://glide.stanford.edu/yichen/research/sec.pdf
- http://secunia.com/advisories/17988/
- http://www.securityfocus.com/archive/1/419487/100/0/threaded
- http://www.osvdb.org/21647
- http://www.osvdb.org/21648
- http://www.osvdb.org/21645
- http://www.osvdb.org/21646
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23564
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.